Regulatory and governance obligations, managed on one platform.
From data protection to corporate governance, XGRC® gives organisations a structured way to show they comply with the laws and codes that matter most in South Africa and internationally. Every obligation has an owner, a control and the evidence to prove it.
GDPR Compliance
XGRC® gives data protection teams a structured way to manage GDPR obligations — lawful basis and consent, data subject requests, DPIAs, and breach notification — on one auditable platform, with every processing activity linked to its evidence.
View compliance guide → RegulatoryPOPIA Compliance
XGRC® gives Information Officers a structured way to manage POPIA obligations — processing conditions, data subject rights, and security compromise reporting to the Information Regulator — on one auditable platform.
View compliance guide → RegulatoryPAIA Compliance
XGRC® gives organisations a structured way to manage PAIA obligations — the published information manual, records classification, and formal access requests — from intake through decision and response, on one auditable platform.
View compliance guide → RegulatoryKing V Governance
XGRC® gives boards and governance teams a structured way to apply King V principles and report on them with evidence — risk governance, combined assurance, and ESG oversight — on one auditable platform. King V is South Africa's corporate governance code, applied on an apply-and-explain basis: it is governance best practice organisations are expected to report against, not a certifiable legal requirement.
View compliance guide →The obligations behind the acronyms.
Regulators rarely ask whether you have a policy. They ask what you did, when, and who approved it. These are the requirements that most often need evidence.
POPIA Protection of Personal Information Act 4 of 2013
Lawful processing of personal information, security safeguards (section 19) and notifying the Information Regulator and data subjects of security compromises (section 22).
PAIA Promotion of Access to Information Act 2 of 2000
A current PAIA manual, and a decision on each access request within 30 days, which can be extended once by up to 30 days.
King V King Code on Corporate Governance
Board oversight of risk, compliance, technology and information, with disclosure of how the principles are applied.
GDPR EU General Data Protection Regulation
Applies to South African organisations that offer goods or services to people in the EU, or monitor their behaviour.
One register, one trail of evidence.
Most compliance teams track obligations in a spreadsheet and prove them with documents scattered across drives and inboxes. That works until a data breach, an access request or an audit arrives, and the team has days to show what happened.
In XGRC®, each obligation from POPIA, PAIA, King V or GDPR sits in one register. It links to the policy that addresses it, the control that puts it into practice, the person who owns it and the evidence that shows it works. Reviews are scheduled, overdue items are flagged, and every change is recorded in the audit trail.
When something goes wrong, the same platform runs the response. A POPIA security compromise runs through a structured workflow that includes the Information Regulator notification steps. A PAIA request is logged on the day it arrives and tracked through assessment, decision and any appeal against the statutory timeline. The board sees one picture of regulatory exposure instead of a set of separate reports.
Beyond data protection and governance
- Health and safety. OHS Act 85 of 1993 and, on mines, the MHSA 29 of 1996. Safety management →
- Environment. NEMA 107 of 1998, licences and permit conditions. Environmental compliance →
- Suppliers. B-BBEE verification and supplier documents under the B-BBEE Act 53 of 2003. Vendor management →
- Controls. Proving that the controls behind your obligations actually work. Internal controls →
Working towards certification as well? See ISO compliance for readiness guides to ISO 9001, 14001, 45001, 27001 and more.
Common questions.
Who enforces POPIA and PAIA in South Africa?
The Information Regulator. It oversees both POPIA and PAIA, receives security compromise notifications under POPIA section 22, and can investigate complaints, issue enforcement notices and impose administrative fines.
How quickly must we answer a PAIA request?
A private or public body must decide on a request within 30 days of receiving it. The period can be extended once, by up to 30 more days, in the circumstances PAIA allows, and the requester must be told of the extension and the reason for it.
Does GDPR apply to a South African company?
It can. GDPR applies to organisations outside the EU when they offer goods or services to people in the EU or monitor their behaviour there. Many South African organisations therefore manage GDPR and POPIA side by side, and much of the evidence overlaps.
Is King V compliance mandatory?
The King Code is voluntary, but the JSE Listings Requirements reference it for listed companies, and many regulators, funders and public entities expect it. In practice boards need to show how they apply the principles, which takes evidence rather than a policy statement.
What does a regulatory compliance platform do that a spreadsheet does not?
It keeps a live register of obligations, links each one to an owner, a control and the evidence that proves it, schedules reviews, and keeps a full audit trail. When a regulator, auditor or board asks, the answer is a report rather than a hunt through email.
See your obligations in one register.
We will show you how POPIA, PAIA and King V obligations are owned, evidenced and reported in XGRC®.
Book a demo